Node.js应用本地可连远程MySQL,部署cPanel后连接被拒绝
Let’s break this down—your app works everywhere except cPanel, and you’re hitting that ECONNREFUSED error on port 3306. You’ve already ruled out the obvious (valid code, DB external access, correct credentials), so the most likely culprit is cPanel’s outbound port restrictions. Here’s what to check and fix:
1. Verify cPanel’s Firewall Outbound Rules
Most cPanel hosting providers block outbound traffic on common database ports like 3306 by default—even if you can ping the DB server (ping uses ICMP, not the TCP protocol MySQL relies on).
- Log into your cPanel dashboard, look for security tools like ConfigServer Security & Firewall (CSF) or your host’s custom firewall interface.
- Check if port 3306 is allowed in the outbound rules. If not, add it to the allowed list for the target DB IP
185.248.177.110. - If you don’t have permission to modify firewall settings, submit a support ticket to your host asking them to open outbound access to
185.248.177.110:3306.
2. Test Port Connectivity in cPanel Terminal
To confirm it’s a port block, run this command in your cPanel terminal:
telnet 185.248.177.110 3306
If you get a "Connection refused" or timeout, that’s solid proof the port is being blocked. If it connects, you can move on to other checks.
3. Tweak Your MySQL SSL Configuration
You already have ssl: true in your code, but cPanel’s environment might require explicit SSL certificate configuration. Try adding a CA certificate (most cloud DB providers offer official CA certs for download):
const fs = require('fs'); var con = mysql.createConnection({ host: config.get("db.host"), port: 3306, user: config.get("db.user"), ssl: { ca: fs.readFileSync('/path/to/your/ca-cert.pem') // Path to the cert file in your cPanel app directory }, password: config.get("db.password"), database: "auth", });
Upload the CA cert to your cPanel app’s directory and update the path accordingly.
4. Try Alternative Ports or SSH Tunneling
- Some DB providers offer alternative ports (like 33060) to bypass port blocks. Check your DB provider’s docs and update the
portvalue in your connection config. - If your host allows SSH tunneling, set up a tunnel from your cPanel server to the DB server, then have your Node app connect to the local tunnel port (e.g.,
localhost:3307) instead of the remote DB IP.
5. Check cPanel Node.js Deployment Restrictions
If you’re using cPanel’s built-in Node.js manager (like Passenger), double-check if there are any network access restrictions enabled. Some hosts limit external connections for Node apps by default—look for settings like "Allow External Network Requests" in your app’s Node.js configuration panel.
I’ve helped troubleshoot this exact issue multiple times, and 9 times out of 10 it’s a firewall blocking outbound 3306. Start with the firewall check, and you’ll likely get it sorted quickly.
内容的提问来源于stack exchange,提问作者Hugo Alexandre

